How to Filter on the Content-type Header in OAG
(Doc ID 2802141.1)
Last updated on AUGUST 26, 2021
Applies to:Oracle API Gateway - Version 126.96.36.199.0 and later
Information in this document applies to any platform.
The usecase here has vulnerability related to content type in OAG.
After using the filter "Content Type" and setting the format use to application/json only, a 200-Ok response is being received, even when passing a content type header in the request other then application/json.
Analysis of this filter shows the following:
The Filter filter works on Content-Body and filters it if data within body is not JSON type
It doesn't work on Header's Value where it should reject the request if the header value is not "application/json"
Is there a way that the Content-type header value can be detected and used to filter messages?
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document